Skip to main content
princes
Staff
Staff
October 21, 2024

Technical Tip: Auto failover to secondary SSL VPN remote gateway not working in FortiClient

  • October 21, 2024
  • 0 replies
  • 2585 views
Description This article describes that if users are using FortiClient to connect with an SSL VPN configured on the FortiGate, then they have a primary and secondary remote gateway for fail-over in case the primary goes down. Now, in this setup, the control to start SSL negotiation is on the endpoint level (FortiClient).

FortiGate will always respond from the gateway where it received SSL negotiation packets.
Scope FortiClient.
Solution

This can be verified with a packet sniffer on FortiGate, which only receives traffic from the primary gateway. If the primary gateway goes down, it will not do automatic fail-over (For the free version of FortiClient, up to version 7.4.3 GA).

 

Screenshot 2024-10-21 144044.png

 

If the primary gateway goes down user needs to change the remote gateway manually (For the free version of FortiClient, up to version 7.4.3 GA).

 

Here are the workarounds to make this auto-fail-over for the SSL gateway possible:

 

  1. Subscribe to a FortiClient EMS is a subscription-based service, so multiple remote gateways can be configured with auto-fail-over mode.
  2. Manually change the remote gateway each time a failover is required.
  3. Or create a single DDNS instead of multiple IP addresses (those should be resolved in any of the active Interface IP addresses on FortiGate).

 

Related document:

Configuring a backup VPN connection